SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-36804

Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

KEVHIGH 8.8EPSS 99.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
99.17% probability · 100th percentile
CISA KEV
Listed 30 September 2022 · due 21 October 2022
Weakness
CWE-78, CWE-88
Affected
atlassian/bitbucket
Source
security@atlassian.com

CISA notes

Apply updates per vendor instructions. https://jira.atlassian.com/browse/BSERV-13438; https://nvd.nist.gov/vuln/detail/CVE-2022-36804

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.